TL;DR:
- The UK Product Security and Telecommunications Infrastructure (PSTI) Act 2022 came into force on 29 April 2024 — manufacturers, importers, and distributors of consumer connectable products sold in the UK must comply with minimum security requirements
- Three core requirements: ban on universal default passwords, a published vulnerability disclosure policy, and transparency about the minimum security update support period
- Enforcement falls to the Office for Product Safety and Standards (OPSS); fines can reach £10 million or 4% of global qualifying turnover — whichever is higher — for serious violations; smaller penalties apply for documentation and notification failures
If your small business sells smart home devices, wireless cameras, routers, smart meters, baby monitors, fitness trackers, or any other product that connects to the internet or a local network, the PSTI Act 2022 applies to you. It came into force on 29 April 2024 and by mid-2026, the OPSS has moved beyond the initial awareness phase into active enforcement.
This guide covers what the law requires, who it applies to, and the practical steps to get compliant if you have not already done so.
Who the PSTI Act Applies To
The Act covers “relevant connectable products” — consumer products that can connect to the internet (internet-connectable) or to other devices (network-connectable). The definition is deliberately broad:
In scope: Smart TVs, routers and modems, home security cameras, smart speakers and displays, smart plugs and switches, baby monitors, wearable fitness devices, smart doorbells and locks, connected toys, smart home hubs, wireless access points.
Out of scope (for the consumer security requirements): Charge-only cables with no data capability, medical devices regulated under separate legislation, electric vehicle charge points (regulated separately), smart meters (regulated by Ofgem), desktop and laptop computers, smartphones and tablets (considered to have separate security frameworks).
The key roles that create obligations:
- Manufacturer — any business that makes a relevant connectable product for supply in the UK, or puts its name or trademark on a product made by someone else
- Importer — a business established in the UK that places products from non-UK manufacturers on the UK market
- Distributor — anyone who makes the product available on the UK market who is not the manufacturer or importer
If you import connected products from China or the EU and sell them in the UK, you are the relevant importer and carry the compliance obligations even if the original manufacturer is not UK-based.
The Three Core Requirements
1. Unique or user-set passwords — no universal defaults
Products must not come with a universal default password — the same password used on every unit of the same model, or a predictable password derived from publicly available information (like the device’s MAC address).
In practice this means either:
- Each device is shipped with a unique password (printed on the device or in the box), or
- The user is required to set a password during initial setup before the device connects to a network
Password reset mechanisms must also restore the device to a unique or user-set password rather than a shared default. The era of “admin/admin” or “1234” as factory defaults is legally over for UK-market products.
2. Publish a vulnerability disclosure policy
You must have a published vulnerability disclosure policy (VDP) that tells security researchers how to report security vulnerabilities to you and commits to a response. The minimum the VDP must include:
- Contact details for submitting a security vulnerability report
- A statement that you will not pursue legal action against researchers who follow the policy and act in good faith
- Information about expected response timelines
The VDP must be accessible on your public website. It does not need to be complex — a simple page with an email address and a statement of intent meets the legal minimum. NCSC publishes a VDP template specifically for small and medium-sized businesses.
3. Declare the minimum security update period
Before purchase, and for the duration of the time you supply the product, you must clearly communicate how long the product will receive security updates. This information must be:
- Available at the point of sale (website product listing, retail packaging, or both)
- Stated in specific time periods (“security updates will be provided until 31 December 2027”) rather than vague commitments (“for a reasonable period”)
If a product has reached end of security support, this must be clearly communicated. You cannot simply stop providing updates without disclosure.
What You Must Document
The PSTI Act requires manufacturers and importers to maintain a Statement of Compliance — a document that describes how the product meets the three security requirements. You don’t file this with the OPSS proactively, but you must be able to produce it on request.
The statement must cover:
- Product name and model number
- How the password requirement is met
- The URL of the vulnerability disclosure policy
- The security update period
Keep this documentation for the period during which the product is on the market plus five years.
Enforcement and Penalties
The Office for Product Safety and Standards (OPSS) is the enforcement authority. Enforcement powers include:
- Compliance notices — requiring a business to take specific remediation steps
- Stop supply notices — halting UK sales of a non-compliant product
- Recall notices — requiring products already sold to be recalled
- Monetary penalties — up to £10 million or 4% of global qualifying turnover for the most serious violations; up to £2,000 per day for ongoing non-compliance with a compliance notice
Initial enforcement has focused on awareness and guidance, but OPSS has made clear it will pursue penalties for deliberate non-compliance or failure to respond to compliance notices. By 2026, imported consumer electronics from unregistered suppliers are a priority enforcement area.
Practical Steps for Small Businesses
Step 1 — Identify whether your products are in scope
List every product you sell that connects to a network or to other devices. Check the full OPSS guidance on the PSTI Act (available on GOV.UK) for edge cases. If in doubt, treat it as in scope.
Step 2 — Audit current password practices
Check whether any of your products ship with universal default passwords. If they do, you need to either change the manufacturing process to generate unique per-device credentials, or implement a mandatory password setup flow in the onboarding process.
Step 3 — Publish a vulnerability disclosure policy
If you don’t have one, write one and publish it on your website. The NCSC small business VDP template takes under an hour to adapt. Designate a monitored email address for receiving reports.
Step 4 — Determine your security update commitment
How long will you provide security updates for each product? This requires an honest internal conversation about product lifecycle and support costs. Once you have a date, add it to your product listing pages and packaging.
Step 5 — Create your Statement of Compliance
Document what you’ve done for each product model. Keep this in a place where it can be retrieved quickly if OPSS contacts you.
If You Import Products from Outside the UK
If you source connected products from overseas suppliers, the compliance obligation is yours as the importer. Your supplier’s compliance claims are not transferable to you for UK regulatory purposes.
Before importing a new product line, ask your supplier for:
- Evidence of unique or configurable password implementation
- Their vulnerability disclosure process
- Their stated security update commitment
Build contractual obligations into supplier agreements that require them to maintain security updates for a defined period and notify you of security vulnerabilities. If a product is sold on your brand rather than the manufacturer’s, you carry full manufacturer responsibilities under the Act.
Resources
- GOV.UK — Product Security and Telecommunications Infrastructure (PSTI) Act guidance: the authoritative source for scope, requirements, and compliance
- NCSC — Vulnerability Disclosure Toolkit: template VDP and guidance for smaller organisations
- OPSS — Product Safety for Businesses: includes the PSTI Act compliance checklist
The PSTI Act was written to close a real gap: millions of UK homes running connected devices with known-bad default passwords, no vendor contact for reporting security flaws, and no clarity about how long software support would last. Compliance is not technically burdensome for businesses that build products properly. The businesses most at risk of enforcement are those that source cheap connected products for resale without verifying the security baseline.